Cyber Essentials Plus in Manchester: what audit day actually looks like
Cyber Essentials Plus is not a form. It's a hands-on audit — an assessor on your site or on a call, testing your real laptops, your real inbox, your real cloud tenancy. Here's what actually happens on the day, what fails, and how to walk in ready.

We put a Manchester manufacturer through their Cyber Essentials Plus audit last month. It went cleanly. It went cleanly because we had spent six weeks getting them ready. The audit day itself took a little over three hours. And the difference between a clean pass and a rework was — in the end — three specific things, all of which are worth writing down for the next business considering it.
Cyber Essentials Plus is a genuinely different animal to the self-assessed Cyber Essentials, and the confusion between the two is the single most common reason we get called in halfway through a failing audit. Cyber Essentials is a questionnaire you fill in, sign off on, and pay for. Plus is what happens when an actual IASME-accredited assessor sits with your real fleet, runs real tests against your real endpoints, and either signs the certificate or hands you a list of things to fix and re-book. IASME's own published guidance is clear that Plus is a hands-on technical audit against the same five controls, done via a mix of remote testing and — for larger or more sensitive estates — an on-site visit. This is why buyers ask for Plus. It's not a self-attestation. Somebody with authority came and checked.
Here's what the day actually looks like when it's booked through us, from an assessor's arrival in Manchester to the certificate landing in your inbox.
What the assessor does when they arrive
For a fifteen-to-fifty-person Manchester business, the audit is usually a hybrid: a Teams call for most of it, plus an in-person visit only if there's on-prem infrastructure that has to be poked. The assessor turns up (physically or virtually) at nine, and the first thing they ask for is the completed self-assessment questionnaire — the version that was submitted for the CE base certification you should already hold. That gets treated as the assertion the business has made about itself, and the whole audit is essentially a structured test of whether that assertion is true.
The assessor then wants access to three things. A representative sample of end-user devices — usually four or five laptops from across the business, chosen by them not by you, ideally including at least one director and one shop-floor or field-based user. Access to the Microsoft 365 or Google Workspace tenancy admin console (view-only is fine). And a phishing-test target — usually a user's real inbox, so they can send a couple of test payloads to a monitored mailbox. Nothing they do is destructive. Everything they do is documented and repeatable.
The five things they will actually test
The five Cyber Essentials controls are the framework, but the assessor tests them as five specific practical questions.
One, firewalls. Do the internet-facing devices have an inbound firewall enabled with default-deny? On end-user laptops this means the Windows Defender Firewall is on and configured, and the local admin can't casually switch it off. On any perimeter appliance — office firewall, VPN — is it currently in support, current on firmware, and configured with a documented ruleset? They'll ask to see the firmware version. They may ask you to prove the SSL VPN portal isn't publicly reachable, or that management interfaces don't listen on the WAN.
Two, secure configuration. Do the sampled laptops have local guest accounts disabled? Are default passwords changed on any deployed appliances? Is autorun off? Is the shipping OEM bloatware — trial antivirus, unwanted browsers — removed? On a decently managed Intune tenancy this is a five-minute check. On an unmanaged fleet, this is a day.
Three, user access control. Is MFA enforced on every user, including admin accounts? Are the number of global administrators reasonable (usually two or three, break-glass documented)? Is there a written joiners/movers/leavers process, and can you show evidence of a recent leaver's account being disabled inside 24 hours of exit? This last one gets a lot of businesses. If your last leaver's Microsoft 365 licence is still active three months later, that's a fail.
Four, malware protection. Every sampled device must have working, up-to-date malware protection. On Windows this is Defender in most cases, and the assessor will actually download a benign EICAR test string to confirm it's blocked in real time. On Macs it's a supported endpoint product. On any Bring-Your-Own-Device that touches business data — that phone the sales director reads email on — there has to be either a managed profile or a hard containerisation that keeps business data out of the personal side.
Five, security update management. All operating systems and applications on the sampled devices must be patched to within fourteen days of a critical update being released. This is where the largest gap tends to sit, and it's the one that trips businesses who thought they were compliant. The assessor doesn't accept "we patch on Patch Tuesday." They open Settings, they look at Windows Update history, and they compare it to the current NCSC Cyber Essentials technical requirements, which — in the current update, live at the time of writing — put the ceiling at fourteen days from vendor release for anything rated high or critical. If a sampled laptop is three months behind on a critical patch, that laptop fails, and depending on how many of the five sampled devices fail, the audit fails.
What actually fails
Across the businesses we put through Plus each year, the failures cluster into three categories. The first is patch cadence — always. The second is a leaver whose account is still active or whose device wasn't collected. The third is a BYOD phone with business email set up outside of a managed policy. Almost every rework we've ever had to do sits somewhere in those three.
None of them are surprises. All of them are boringly preventable. The reason they fail isn't technical — the tooling to fix them all exists and is affordable. The reason they fail is that nobody in the business has been made specifically accountable for keeping them clean between one certification and the next.
Why more Manchester businesses are asking for Plus this year
There are two forces pulling businesses toward Plus in 2026 rather than sticking with base Cyber Essentials. The first is buyer pressure. Public-sector procurement — councils, NHS trusts, MoD supply chain — increasingly names Plus specifically in tender documents. If you sell to a Manchester council, a Greater Manchester housing association, or a health board, the questionnaire almost certainly now asks for Plus, not the self-assessed version. The base certificate ticks a smaller and smaller number of tender boxes each year.
The second is cyber insurance. Insurers have been asking harder questions on renewal for three years running, and 2026 is the year several major UK underwriters have started explicitly rewarding Plus with materially better premiums, particularly for manufacturing and professional-services SMEs — sectors where the 2025-2026 Cyber Security Breaches Survey shows breach rates continuing to climb. The economics of the certificate are increasingly straightforward: the audit and remediation cost is often less than a single year's premium saving.
What the six weeks before audit day looks like when we do it
The reason we can confidently say a client is audit-ready is because the six weeks preceding the audit follow a fixed shape. Week one is a full gap analysis — we run our audit script against the fleet and produce a written list of exactly what would fail today and why. Weeks two to four are the remediation work: patch cycle brought current, MFA rolled to any user still without it, Intune or an equivalent MDM configured against the CE+ baseline, leaver process written down and tested against a real recent leaver's paperwork, BYOD tightened. Week five is a dry run — we run the same tests the assessor will run, on the same sample of devices, and any failures go back into remediation. Week six is the audit itself.
At the end of it, the certificate arrives inside about a fortnight. You hold it for a year, and — this is the part that determines whether the next renewal is easy or painful — the twelve months in between are managed. Patches get applied. Leavers get offboarded. New starters get enrolled into the same baseline the audit approved. It stops being an event and starts being maintenance. That's the whole shape of doing this properly.
If you're a Manchester business considering Plus for the first time — whether because a customer asked for it, your insurer prompted you, or you're just tired of ticking "in progress" on a tender question — the honest first conversation is a thirty-minute call where we tell you whether you're weeks away or months away from being audit-ready. It costs nothing and it tends to save several rounds of frustrating discovery. Get in touch or read more about how we run the certification end-to-end.
FAQ
How much does Cyber Essentials Plus cost in Manchester?
The certification body's assessor fee sits in the £1,500-£2,500 range depending on the size of the estate, plus VAT. The bigger cost, if it applies, is the remediation work — for a small Manchester business already running a decent managed IT service and Intune, remediation might be a couple of days. For a business coming in cold with an unmanaged fleet, it's often four to six weeks of work. We quote the two lines separately so you can see what's certification and what's improvements to your estate. The annual renewal, once you're in the rhythm, is much cheaper than the first year.
Do we need base Cyber Essentials before we can do Plus?
Yes. Plus is essentially the audit of the claims made in the base self-assessment, so you have to hold the base certificate first (or have it in flight in parallel — some assessors will run them together). We usually do them as a single project.
What's the difference between Cyber Essentials Plus and ISO 27001?
Plus is a technical audit against five specific controls, done by an assessor over a couple of days, and it costs low four figures a year. ISO 27001 is a full information security management system with policies, risk registers, internal audits and management reviews — a six-to-nine-month project the first time, and a running annual cost. We wrote about when ISO 27001 is worth it for a 20-person business and when it isn't. Short answer: most Manchester SMEs should be at Plus, and only some should be at 27001 on top.
How long does the audit itself take?
For a 15-50 person business, the audit day is usually three to five hours, most of it on a Teams call, with the assessor testing a sample of five or so laptops. The full end-to-end certification project — gap analysis, remediation, audit, certificate — is typically six to eight weeks.
Can we do it if we don't have a managed IT provider?
You can — the certification body doesn't require one. But the practical reality is that Plus tests things that need to be in place already, so if your fleet is unmanaged, someone has to do the management work first. That's often what pulls a business into a managed service in the first year. If you'd rather stay unmanaged and just get the certificate, we can quote the remediation as a fixed project and hand it back to you.
How often do we have to renew?
Annually, without exception. Plus is a twelve-month certificate. If it lapses, tenders that require it stop treating you as compliant on the day it expires. We diary-manage the renewal for every client we certify.
Ready to talk to a real Manchester MSP?
If any of this raised a question about your own setup, get in touch. We'll give you a straight answer — no sales pitch, no scaremongering.
Talk to a human